Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-j69q-r9wj-j9g6

больше 3 лет назад

The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j5jj-f68h-7qh9

больше 3 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-j545-cjf3-8m8v

больше 3 лет назад

When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77.

EPSS: Низкий
github логотип

GHSA-j4rm-v56v-f2j9

больше 3 лет назад

Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP archive.

EPSS: Низкий
github логотип

GHSA-j2gp-w4x2-2gc7

почти 4 года назад

Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than CVE-2010-1028.

EPSS: Низкий
github логотип

GHSA-j282-cmxq-gm6v

почти 4 года назад

Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header

EPSS: Низкий
github логотип

GHSA-hxwg-8hr4-ch36

больше 3 лет назад

Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hx9x-3jpr-5g63

почти 4 года назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-hx83-hmj3-pffc

больше 1 года назад

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-hx45-gw2r-332x

больше 3 лет назад

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

EPSS: Низкий
github логотип

GHSA-hvw3-mf8r-hgvr

больше 3 лет назад

A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack. This vulnerability affects Firefox < 51.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-hv5h-mf6r-57mp

больше 2 лет назад

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 109.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hqww-p73m-wmm6

больше 3 лет назад

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

EPSS: Низкий
github логотип

GHSA-hqqw-w569-86hm

больше 3 лет назад

Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.

EPSS: Низкий
github логотип

GHSA-hqqc-crjh-93xx

больше 3 лет назад

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.

EPSS: Низкий
github логотип

GHSA-hq9m-2fcc-v974

больше 3 лет назад

The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandling the element. This vulnerability affects Firefox < 56.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-hq3w-qjwj-w8fp

почти 4 года назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

EPSS: Низкий
github логотип

GHSA-hph5-qh8m-x8v8

больше 3 лет назад

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

EPSS: Низкий
github логотип

GHSA-hp43-m6jc-vrgr

больше 3 лет назад

Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

EPSS: Низкий
github логотип

GHSA-hp3c-mm39-w8vj

больше 3 лет назад

The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, which allows remote attackers to bypass the Same Origin Policy via crafted API calls that access sensitive information within the JSON data of an alarm.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-j69q-r9wj-j9g6

The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-j5jj-f68h-7qh9

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-j545-cjf3-8m8v

When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affects Firefox < 77.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-j4rm-v56v-f2j9

Buffer underflow in libjar in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP archive.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-j2gp-w4x2-2gc7

Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than CVE-2010-1028.

1%
Низкий
почти 4 года назад
github логотип
GHSA-j282-cmxq-gm6v

Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header

0%
Низкий
почти 4 года назад
github логотип
GHSA-hxwg-8hr4-ch36

Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-hx9x-3jpr-5g63

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

4%
Низкий
почти 4 года назад
github логотип
GHSA-hx83-hmj3-pffc

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-hx45-gw2r-332x

When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't control, resulting in a spoofing attack. This was fixed by changing external protocol prompts to be tab-modal while also ensuring they could not be incorrectly associated with a different origin. This vulnerability affects Firefox < 82.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hvw3-mf8r-hgvr

A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on e10s systems, allowing for a denial of service attack. This vulnerability affects Firefox < 51.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-hv5h-mf6r-57mp

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 109.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hqww-p73m-wmm6

If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was not upgraded to https. This vulnerability affects Firefox < 70.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hqqw-w569-86hm

Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hqqc-crjh-93xx

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-hq9m-2fcc-v974

The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandling the element. This vulnerability affects Firefox < 56.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-hq3w-qjwj-w8fp

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

3%
Низкий
почти 4 года назад
github логотип
GHSA-hph5-qh8m-x8v8

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-hp43-m6jc-vrgr

Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-hp3c-mm39-w8vj

The Alarm API in Mozilla Firefox before 33.0 and Firefox ESR 31.x before 31.2 does not properly restrict toJSON calls, which allows remote attackers to bypass the Same Origin Policy via crafted API calls that access sensitive information within the JSON data of an alarm.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу